Security and confidentiality
Protecting company, employee, customer, and partner information is part of earning peace of mind.
- Use approved accounts, devices, services, and access methods for company work.
- Request only the access needed for your responsibilities and never share credentials.
- Store and share information only in approved locations and with intended recipients.
- Verify unusual requests involving credentials, payments, personal data, or access.
- Keep important actions traceable and reversible when the system allows it.
- Report suspected loss, exposure, phishing, unauthorized access, or device compromise immediately through the designated security channel.
- Return company information, equipment, and access when responsibilities change.
Do not publish, forward, or use confidential information for a purpose that has not been approved. When classification or handling requirements are unclear, pause and ask the appropriate owner.
:::caution Policy details pending Security must add approved tools, data classifications, retention requirements, incident contacts, and role-specific controls before this page is complete. :::
Guidance type: Policy framework
Owner: Security